Site to Site VPN ER605

Site to Site VPN ER605

Site to Site VPN ER605
Site to Site VPN ER605
Friday - last edited Monday
Tags: #VPN
Model: ER605 (TL-R605)  
Hardware Version: V1
Firmware Version:

I am trying to set up a site to site VPN (ipsec) for data on specific ports.

 

all other data (internet traffic) should run through the local isp.

 

somehow i cannot get it up and running between the two ER-605's

 

no open vpn.

 

Site one LAN: 192.168.1.xx

Site two LAN: 192.168.168.xx

 

thank you in advance

  0      
  0      
#1
Options
1 Accepted Solution
Re:Site to Site VPN ER605-Solution
Monday - last edited Monday

Hi @AJC01 

Thanks for posting in our business forum.

You can take a look at this:

How to set up Site-to-Site Manual IPsec VPN Tunnels on Omada Gateway via Omada Controller

 

Or give full details about your network environment and configs.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
Recommended Solution
  1  
  1  
#2
Options
17 Reply
Re:Site to Site VPN ER605-Solution
Monday - last edited Monday

Hi @AJC01 

Thanks for posting in our business forum.

You can take a look at this:

How to set up Site-to-Site Manual IPsec VPN Tunnels on Omada Gateway via Omada Controller

 

Or give full details about your network environment and configs.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
Recommended Solution
  1  
  1  
#2
Options
Re:Site to Site VPN ER605
Monday - last edited Monday

  @AJC01 

thank you for the reply.

 

I have this network situation:

 

                   Site 1                                                       Site 2

 

                                            -----------------------------------------

                                            | -------------------------------------  |        

                                            | |                                            | |    

              ISP modem ---------                                              | | 

                      |                     | |                                            | |

------------------ ER605  ------ | |                                            | |  

|                                           | |                                        ISP modem

|                                           | |                                            | |

|                                           | |                                        ER 605 ---------------------------DHCP LAN 

|                                           | |                                           | |        

|                                           | |                                         WIN Server VPN-host (DHCP -VPN)

|                                           | |                                                                    

|                                           | |

|                                           | |      

|                                           | |

workstation 1------VPN-------| |

workstation 2 -----VPN-------- |

etc.

 

 

 

What i'd like

 

Site 1 - ER605 (VPN)  ------------ISP modem ----------------------Site 2----ISP modem ----ER605 (VPN)-----WIN server.

 

Just for certain ports / programms

 

All other internet trafic needs to be routed through the ISP modem directly to the internet

 

 

 

  0  
  0  
#3
Options
Re:Site to Site VPN ER605
Monday

  @AJC01 

 

you want IPsec site to site, or lan to lan as it is called in stand alone, It's pretty simple, make sure you have a public IP address on both routers, then go to page 153 in the manual.

 

I don't know if you are using stand alone or controller, the manual is for stand alone

 

https://static.tp-link.com/upload/manual/2023/202310/20231009/1910013510_ER605(UN)_UG.pdf

  0  
  0  
#4
Options
Re:Site to Site VPN ER605
Monday
Thank you, how do i accomplish than only certain ports get routed over the vpn ? and all other traffic over the isp - internet ?
  0  
  0  
#5
Options
Re:Site to Site VPN ER605
Monday

  @AJC01 

 

first you should get the vpn up and running then you can concentrate on ports then. but to block and open ports you use acl which is also described in the manual i would think

 

  0  
  0  
#6
Options
Re:Site to Site VPN ER605
Monday - last edited Monday

  @MR.S 

 

unfortunatelly, no connection.

 

had both vpn settings next to each other, followed the steps from the manual, no connection

are there any ports i need to open ?

 

 

  0  
  0  
#7
Options
Re:Site to Site VPN ER605
Monday

  @AJC01 

 

Do you have a public IP on the WAN interface of the router? You must have that on both routers or it won't work.

 

  0  
  0  
#8
Options
Re:Site to Site VPN ER605
Monday - last edited Monday

at the wan-ports, i have the lan adress of the isp modem (=gateway)

  0  
  0  
#9
Options
Re:Site to Site VPN ER605
Monday

  @AJC01 

 

no no ports should be opened. when it works you should be able to ping gateway ip from lan to lan, if you get a response then vpn is established

 

  0  
  0  
#10
Options
Re:Site to Site VPN ER605
Monday

AJC01 wrote

at the wan-ports, i have the lan adress of the isp modem (=gateway)

  @AJC01 

 

it won't work, what ip is it? does it start with 192.168.x.x or 10.x.x.x

 

  0  
  0  
#11
Options